Логотип exploitDog
source:"github"
Консоль
Логотип exploitDog

exploitDog

source:"github"

Количество 314 375

Количество 314 375

github логотип

GHSA-3vwr-jj4f-h98x

больше 1 года назад

eZ Publish Remote code execution in file uploads

EPSS: Низкий
github логотип

GHSA-3vwp-294x-6v9c

около 3 лет назад

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

CVSS3: 7.8
EPSS: Средний
github логотип

GHSA-3vwm-fc87-mq6h

около 3 лет назад

Jenkins NS-ND Integration Performance Publisher Plugin disables SSL/TLS certificate validation globally and unconditionally

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-3vwh-qrr4-g3m5

больше 1 года назад

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-3vwh-824w-m2mm

больше 3 лет назад

The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data.

EPSS: Низкий
github логотип

GHSA-3vwh-4gr8-m2f4

около 3 лет назад

CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3vwg-x7c5-rg6m

12 месяцев назад

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vwg-x6p9-p27f

больше 3 лет назад

Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vwg-cxp6-wf3x

больше 3 лет назад

D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.

EPSS: Низкий
github логотип

GHSA-3vwf-8mrh-29c3

11 месяцев назад

A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3vwc-vg65-rpwm

почти 4 года назад

Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.

EPSS: Низкий
github логотип

GHSA-3vwc-j35j-g8jv

почти 2 года назад

An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-3vwc-9hxx-4mr4

больше 3 лет назад

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1379, CVE-2019-1383.

EPSS: Низкий
github логотип

GHSA-3vw9-p3ff-4j6x

больше 3 лет назад

Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted FlashPix file.

EPSS: Низкий
github логотип

GHSA-3vw8-fxch-92g8

около 2 месяцев назад

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-3vw8-44x3-wrr9

больше 3 лет назад

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3vw7-gqq2-ffcx

больше 3 лет назад

In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3vw6-2x4m-gr8r

больше 3 лет назад

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-3vw5-w7rp-h2rf

12 месяцев назад

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

EPSS: Низкий
github логотип

GHSA-3vw4-6555-wh35

3 месяца назад

A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-3vwr-jj4f-h98x

eZ Publish Remote code execution in file uploads

больше 1 года назад
github логотип
GHSA-3vwp-294x-6v9c

In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.

CVSS3: 7.8
55%
Средний
около 3 лет назад
github логотип
GHSA-3vwm-fc87-mq6h

Jenkins NS-ND Integration Performance Publisher Plugin disables SSL/TLS certificate validation globally and unconditionally

CVSS3: 5.9
0%
Низкий
около 3 лет назад
github логотип
GHSA-3vwh-qrr4-g3m5

Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS3: 7.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-3vwh-824w-m2mm

The USAA application 3.0 for Android stores a mirror image of each visited web page, which might allow physically proximate attackers to obtain sensitive banking information by reading application data.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vwh-4gr8-m2f4

CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-3vwg-x7c5-rg6m

Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the sub_452A4 function.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-3vwg-x6p9-p27f

Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vwg-cxp6-wf3x

D-Link DAP-1860 devices before v1.04b03 Beta allow arbitrary remote code execution as root without authentication via shell metacharacters within an HNAP_AUTH HTTP header.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3vwf-8mrh-29c3

A code execution vulnerability exists in the Xiaomi shop applicationproduct. The vulnerability is caused by improper input validation and can be exploited by attackers to execute malicious code.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-3vwc-vg65-rpwm

Multiple integer overflows in OpenOffice.org (OOo) 2.x before 2.4.2 allow remote attackers to execute arbitrary code via crafted EMR records in an EMF file associated with a StarOffice/StarSuite document, which trigger a heap-based buffer overflow.

9%
Низкий
почти 4 года назад
github логотип
GHSA-3vwc-j35j-g8jv

An out of bounds write vulnerability in the AMD Radeon™ user mode driver for DirectX® 11 could allow an attacker with access to a malformed shader to potentially achieve arbitrary code execution.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-3vwc-9hxx-4mr4

An elevation of privilege vulnerability exists when the Windows Data Sharing Service improperly handles file operations, aka 'Windows Data Sharing Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1379, CVE-2019-1383.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vw9-p3ff-4j6x

Apple QuickTime before 7.6.9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted FlashPix file.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-3vw8-fxch-92g8

Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.

CVSS3: 5.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-3vw8-44x3-wrr9

SAP NetWeaver ABAP Server and ABAP Platform (Enqueue Server), versions - KRNL32NUC - 7.22,7.22EXT, KRNL64NUC - 7.22,7.22EXT,7.49, KRNL64UC - 8.04,7.22,7.22EXT,7.49,7.53,7.73, KERNEL - 7.22,8.04,7.49,7.53,7.73, allows an unauthenticated attacker without specific knowledge of the system to send a specially crafted packet over a network which will trigger an internal error in the system due to improper input validation in method EnqConvUniToSrvReq() causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3vw7-gqq2-ffcx

In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5, and all versions of 13.1.x, when BIG-IP is provisioned with PEM or AFM module, an undisclosed input can cause Traffic Management Microkernel (TMM) to terminate.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-3vw6-2x4m-gr8r

Equation Editor in Microsoft Office 2007, Microsoft Office 2010, Microsoft Office 2013, and Microsoft Office 2016 allows a remote code execution vulnerability due to the way objects are handled in memory, aka "Microsoft Office Remote Code Execution Vulnerability".

CVSS3: 8.8
36%
Средний
больше 3 лет назад
github логотип
GHSA-3vw5-w7rp-h2rf

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

12 месяцев назад
github логотип
GHSA-3vw4-6555-wh35

A security flaw has been discovered in itsourcecode Inventory Management System 1.0. Affected is an unknown function of the file /LogSignModal.PHP. The manipulation of the argument U_USERNAME results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be exploited.

CVSS3: 7.3
0%
Низкий
3 месяца назад

Уязвимостей на страницу